CWE-142: Improper Neutralization of Value Delimiters
The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as value delimiters when they are sent to a downstream component.
3 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-1774 — Logs manipulation in BotSense
- CVE-2025-61962 — In fetchmail before 6.5.6, the SMTP client can crash when authenticating upon receiving a 334 status code in a malformed
- CVE-2026-13379 — The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows remote attackers to cause persistent DNS stat
Recently published
- CVE-2026-13379 — The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows remote attackers to cause persistent DNS stat
- CVE-2025-61962 — In fetchmail before 6.5.6, the SMTP client can crash when authenticating upon receiving a 334 status code in a malformed
- CVE-2025-1774 — Logs manipulation in BotSense